The ten points that decide your tier
1) The three tiers in one sentence each
Locked pins you to one satellite position and one frequency on it, permanently tuned and shared. Unlocked gives you a private tuner on one satellite position, cold but free to move anywhere on that position. Dedicated gives you the physical machine and the tuner cards inside it.
Everything else in this guide follows from those three sentences. The tiers are not a quality ladder where the expensive one is simply better — they are three different products that happen to solve overlapping problems. Choosing badly usually means paying for freedom you never use, or discovering three months in that the thing you actually needed was a card slot.
The most common mistake is treating the dedicated server as the "serious" option and the virtual tiers as a budget compromise. That reads the ladder backwards. A dedicated chassis is the right answer to a narrow set of physical requirements. If you do not have one of those requirements, the dedicated tier hands you a rack unit, a power draw, an operating system and an entire software stack to maintain — in exchange for capabilities you will not use.
2) A locked tuner is already hot — that is the whole argument
Because a locked tuner's position and frequency are both chosen when you order it, the demodulator is brought up on that transponder and held there. It is not waiting for instructions. It is already receiving.
This is the single most important practical difference between the tiers, and it is easy to miss on a specification sheet because it does not appear as a number. A locked tuner has already completed carrier acquisition and forward-error-correction lock. When your streamer opens a session, the transport stream is available immediately — there is no tuning step to wait through, because the tuning already happened and never stopped.
For a service that runs continuously, the value of that shows up at the worst possible moments. Every reconnect after a network blip, every restart of your streaming software, every failover to a standby node is a moment when a cold tuner would need to acquire the carrier again before a single packet moved. A hot tuner has nothing to reacquire.
"A tuner that is already locked cannot be slow to lock. The fastest tune is the one that already happened."
— Gleb Sazanov, CTO, SATLINE.TV
There is a second, quieter benefit. While it is running, a locked tuner cannot be retuned by a live SAT>IP command — not by a misconfigured client, not by an automation script that walks a channel list and forgets where it started. For production ingest, that is a feature, not a limitation: the feed cannot drift off its transponder by accident. Choosing which frequency the tuner is locked to is a separate, deliberate action you take in your client area — never something a stray command can do mid-stream.
3) What tune-and-lock actually costs you
Tuning a DVB-S2 or DVB-S2X carrier is not instantaneous. The demodulator must find the carrier, converge on symbol timing, resolve the modulation and code rate, and reach FEC lock before usable data emerges.
On a healthy signal this is quick enough that a human watching a set-top box barely notices it. In a broadcast ingest chain it is a different matter, because it is not one delay — it is a delay that recurs. Every retune pays it again. On DVB-S2X multistream carriers, the demodulator must additionally select the correct input stream by its ISI, and where T2-MI is involved there is further work before the inner transport stream is exposed.
Weak or marginal signal conditions extend the process. A carrier that locks briskly in clear conditions can take appreciably longer when the link margin has been eaten into by rain, and in the worst case the lock is achieved, lost, and reacquired repeatedly. This is precisely the scenario in which a cold-tuning architecture behaves worst and a permanently-held lock behaves best.
None of this is an argument against unlocked tuners. It is an argument for knowing which cost you are paying. If your workload is genuinely dynamic, retune latency is simply the price of the flexibility you are buying, and it is a fair one. If your workload is a fixed lineup that should never change frequency, you are paying it for nothing.
4) T2-MI arrives already decapsulated
T2-MI — the DVB-T2 Modulator Interface — is a wrapper. Several broadcasters distribute terrestrial multiplexes over satellite inside it, which means the stream you receive is not the stream you want until something unwraps it.
Handled conventionally, that "something" is an extra box: a dedicated decapsulator or gateway sitting between the demodulator and the streamer, with its own power supply, its own configuration, its own firmware and its own failure modes. It is a device whose entire job is to remove a layer of packaging.
On the SAT>IP tiers the decapsulation happens in the reception chain before the stream reaches you, so what arrives is the inner transport stream with the PLP already selected. That removes the external box from your architecture — not by making it cheaper or faster, but by making it unnecessary. One fewer device is one fewer thing to monitor, replace, and pay for.
On a dedicated server the situation is different, and this is worth being clear about: the PCIe cards expose standard Linux DVB devices, so T2-MI handling becomes your software stack's responsibility. That is entirely workable — plenty of operators do it — but it is work you own rather than work that is done for you.
The mechanics of T2-MI, PLP selection and inner-TS recovery are covered properly in T2-MI Explained: 10 Reasons Direct Processing Matters.
5) Nothing is filtered for you — you choose the PIDs
The full transponder is available, and what crosses the link is your decision, made per session in the tuning request. Ask for pids=all and the complete multiplex arrives. Ask for an explicit PID list and only those elementary streams are sent. Nobody upstream decides on your behalf which services you are allowed to see.
This is worth separating from a common assumption. A managed tuner service could reasonably be expected to hand over a pre-trimmed stream containing just the services you named at order time. That is not how it works. A locked frequency is a whole transponder, and the whole multiplex is yours to draw on — every service on the carrier, with the original PSI/SI tables intact.
Selection is then a runtime parameter, not a provisioning decision. pids=all gives you the complete MPTS, which is what you want when you are analyzing a carrier, harvesting tables, or feeding a remultiplexer that expects the full stream. An explicit list like pids=0,17,100,101 keeps the link carrying only the services you actually need — useful precisely when you do not want to saturate a WAN path with a dozen channels you will discard on arrival. Both are one URL parameter apart, and you can change your mind without touching the service.
Because the full stream is available on demand, all the analysis you would do against a local tuner still works. Point tsp from TSDuck at it, or open it in Astra's analyzer, and you see the complete service list, the PAT and PMT, the elementary stream PIDs and the per-service bitrates. Nothing has been pre-digested into a shape someone else chose.
Where MPTS or T2-MI encapsulation is present, that layer is unwrapped before delivery so the inner transport stream is what reaches you — but unwrapping a container is not the same as filtering its contents. The services inside remain complete and selectable.
The full pids parameter syntax, along with multistream and T2-MI parameters, is documented in SAT>IP URL Builder & T2-MI Configuration.
This also disposes of the "more hardware is more professional" instinct. Extra physical layers in a signal path do not make it faster; each one is a store-and-forward stage with its own buffer. Receiving an already-decapsulated stream over IP removes those stages while leaving the selection decision with you.
6) Reception redundancy you do not have to build
Both SAT>IP tiers are backed by reception at a separate location, reachable over independent network paths. If one reception point or one route is disrupted, the alternative is already in place.
Building that yourself is a serious undertaking. It means a second physical site far enough away to be genuinely uncorrelated, a second set of dishes and LNBs, network paths that do not share fate with the first, and the monitoring and switching logic to make the pair behave as one service. Every operator who has priced this exercise knows how quickly it stops looking like a line item and starts looking like a project.
On the virtual tiers it is part of the service, delivered from Tier III facilities with N+1 power and redundant cooling, monitored continuously. You are renting the outcome rather than assembling the components.
A dedicated server does not have this property by default, and it is important not to pretend otherwise. One chassis in one rack is one chassis in one rack. It can be made redundant — with a second server, ideally elsewhere, and failover logic you design and test — but that redundancy is yours to build, operate and prove.
7) The billing unit quietly decides your cost curve
Locked tuners are sold by frequency. Unlocked tuners are sold by satellite position. Dedicated servers are sold by chassis. Those three units scale very differently as you grow.
At the published Starter tiers the locked option is €28 against €38 for unlocked — roughly a quarter less — and the gap holds across the range: €55 against €75 at Advanced, €99 against €139 at Professional. If your requirement really is a handful of known transponders, paying the position premium buys you tuning freedom you have already decided not to exercise.
| Tier | Locked (frequencies) | Unlocked (positions) | Difference |
| Starter — 1 unit | €28 | €38 | −26% |
| Advanced — 2 units | €55 | €75 | −27% |
| Professional — 4 units | €99 | €139 | −29% |
The inflection arrives when one position carries many transponders you need. Frequencies bought individually eventually cost more than the position that contains them, and at that point unlocked becomes the cheaper answer as well as the more flexible one. Further along, when demodulator count rather than frequency count is the constraint, a chassis with three cards and twenty-four demodulators changes the arithmetic again.
The honest version of this comparison is that no tier is universally cheapest. What is universally true is that the billing unit should match the shape of your requirement — frequencies if you need frequencies, positions if you need positions, demodulators if you need demodulators.
8) What unlocked tuners are genuinely better at
An unlocked tuner gives you the whole orbital position. Any frequency, any time, as often as you like. For a large class of real work, that is not a nice-to-have — it is the requirement.
EPG harvesting shows the boundary clearly. A locked tuner does deliver the EIT tables for its own transponder — they arrive with the stream, so programme data for those services is yours already. What it cannot do is reach the rest: guide data is spread across transponders, and collecting it means visiting each in turn on a schedule. That requires retuning, which a locked tuner cannot perform. An unlocked tuner walks the position, and the retune cost that is pure waste in a production lineup is simply the mechanism here.
Satellite scanning and discovery behave the same way. Reading NIT tables to find what is actually being broadcast, checking whether a service has moved, validating that a transponder still carries what your documentation claims, building a channel grid from scratch, investigating a feed a customer has asked about — all of it is tuning around, which is exactly what the position purchase buys.
There is a planning pattern worth stealing here: keep one unlocked tuner even when the bulk of the estate is locked. It becomes the instrument you scan and diagnose with, while the locked tuners carry the lineup undisturbed. Diagnostics never touch production, and production never has to be retuned to answer a question.
9) Where dedicated hardware wins — and the one thing it cannot fix
A dedicated server with physical CAM modules is a legitimate and often excellent architecture. What is not true is that it is the only way to handle conditional access — and there is one problem it cannot solve at any price.
The case for a dedicated server with a physical CAM is real. Tuner, CI module and smartcard sit in one chassis, descrambling happens where the signal is demodulated, and there is no IP hop between the two. It is self-contained, easy to reason about, and easy to hand to an engineer as a single unit. If you are building a headend from scratch and conditional access is central to it, this is a sound way to build.
But it is not the only way. Modern professional multi-CAM systems descramble an IP-delivered transport stream and are not bound to a tuner's CI slot. Operators routinely take an MPTS from a SAT>IP tier, carry it over SRT to their own datacenter, and descramble it there with CAM Pro modules and their smartcards. Digital Devices CI descrambling likewise works against SAT>IP channels, and most mainstream streaming software supports it. Older CAMs that must occupy a physical tuner's CI slot are the genuine exception — those do need the tuner and the module in the same box.
GPUs and storage do not care where the stream came from. An encoder needs a card in a slot and a large DVR needs real disks, but that slot and those disks can sit in a server you already own, fed over IP. NVENC does not behave differently because the transport stream arrived over SRT rather than PCIe. The requirement is hardware you control — not tuners and hardware in the same chassis.
So the dedicated tier earns its place on density and coherence: 8, 16 or 24 demodulators from one to three Digital Devices Max SX8 Pro cards, exclusive resource allocation, and one platform where tuners, decryption, transcoding and storage all live together.
And here is what no dedicated server can do: receive a beam that does not reach it. This is the hard limit, and it is geographic rather than technical. If a satellite's footprint does not illuminate your location, or the orbital position sits below your horizon, then no dish, no tuner card and no chassis will bring you that signal. Buying more hardware cannot move your building. A SAT>IP tier receives where the beam actually lands and hands you the stream over IP — which makes positions and beams that are simply unavailable at your site available anyway. That is a capability, not a cost saving, and it is the one argument for the virtual tiers that hardware cannot answer.
The same logic applies in miniature when you already own the hardware. Short a few transponders? You need frequencies, not another chassis — extra frequencies are available as an add-on to an existing dedicated server or VPS at €10 per frequency. Against €299 a month for the smallest dedicated box, adding the two or three you are actually missing is not a close call. Note this is an add-on rate for an existing service rather than a standalone product — a first locked tuner starts at the €28 Starter tier.
One honest note on the tier itself: the cards are not the difficulty. Max SX8 Pro units present as standard Linux DVB devices, no vendor drivers required, so anything speaking the Linux DVB API or SAT>IP finds them. The weight is that you own the whole software stack above them — streaming platform, configuration, updates, monitoring, root administration — plus rack space, power draw, and the attention a machine you administer will want at inconvenient hours.
10) Why real deployments end up hybrid
Almost nobody who runs satellite ingest at scale for long ends up on a single tier. The tiers are complementary, and mature estates reflect that.
The pattern that recurs looks like this. Locked tuners carry the stable production lineup, because that lineup is exactly what locked tuners are for: fixed, pre-warmed, cheapest per frequency, redundantly received. One unlocked tuner sits alongside for scanning, EPG collection and diagnostics. Dedicated hardware carries what genuinely benefits from being co-located — dense demodulator counts, a transcoding tier, a recording array — and does not carry traffic that a virtual tuner could carry more cheaply.
The most common shape is not three tiers bought at once, though. It is an operator who already owns servers, CAM modules and GPUs, discovering they are short a few transponders. The instinct is to price another chassis. The cheaper answer is almost always to add the missing frequencies as locked tuners and feed them into the hardware that already exists — the CAM descrambles an IP-delivered MPTS just as happily as a locally tuned one.
Arriving there tends to be incremental rather than planned. A new position is worth exploring, so an unlocked tuner is added; once the useful transponders are identified, those move to locked and the unlocked tuner returns to scanning duty. A contract brings channels from a position you cannot see, so a locked frequency is added rather than a rack unit.
The mental model that holds up: locked is where production lives, unlocked is how you explore, dedicated is where density and co-location earn their keep. Estates built this way stay cheaper than all-dedicated and more capable than all-locked, and they degrade gracefully — a scanning problem never becomes an outage.
FAQ
What is the difference between a locked and an unlocked SAT>IP tuner?
A locked tuner is sold per frequency: you nominate the transponder when you order, and the tuner is held on it permanently. An unlocked tuner is sold per satellite position and can be retuned to any frequency on that position at any time. Locked is cheaper and starts streaming immediately because the lock is already established; unlocked costs more and buys tuning freedom.
Why does a locked tuner start streaming faster?
Because the tuning has already happened. Carrier acquisition and FEC lock were completed when the tuner was provisioned, and the lock is held continuously. Opening a session does not trigger a tune — the transport stream is already flowing. An unlocked tuner must acquire the carrier and reach lock each time it is pointed at a new frequency.
Can I use a locked tuner for EPG grabbing?
Yes — but only for the services carried on that one transponder. The EIT tables arrive with the stream like any other SI data, so requesting pids=all gives you everything needed to extract programme data for that multiplex. What a locked tuner cannot do is collect EPG for the rest of the position, because guide data is spread across transponders and reaching them means retuning. If your EPG needs are satisfied by the transponders you already receive, locked tuners are sufficient. If you need guide data for services you do not otherwise carry, add an unlocked tuner and let it walk the position on a schedule.
Do I need a dedicated server to descramble encrypted channels?
Usually not. A dedicated server with the CI module and smartcard beside the tuner is a clean, self-contained way to do it, and a perfectly good choice when you are building a headend around conditional access. But modern professional multi-CAM systems descramble an IP-delivered transport stream and are not tied to a tuner's CI slot — operators commonly carry an MPTS from a SAT>IP tier over SRT into their own datacenter and descramble there with CAM Pro modules and smartcards. Digital Devices CI descrambling also works against SAT>IP channels, and most mainstream streaming software supports it. The real exception is an older CAM that must sit in a physical tuner's CI slot.
Can a dedicated server receive a satellite beam that does not reach my location?
No. If the satellite's footprint does not illuminate your site, or the orbital position sits below your horizon, no dish, tuner card or chassis will bring you that signal — this is a geographic limit rather than a technical one, and buying more hardware cannot move your building. A SAT>IP tier receives where the beam actually lands and delivers the stream to you over IP, which is the one capability hardware cannot substitute for.
Is a dedicated server always better than a virtual tuner?
No. It is better when you want density and co-location — many demodulators, with CAM modules, GPUs and storage in the same platform. Absent that, it gives you more to operate rather than more capability: rack space, power, an operating system and a complete software stack all become yours. And it cannot do the one thing the virtual tiers can, which is receive a beam that does not reach your location. For a fixed lineup with hardware you already own, locked SAT>IP tuners are simpler and substantially cheaper.
How is T2-MI handled across the three tiers?
On both SAT>IP tiers, T2-MI decapsulation happens in the reception chain, so you receive the inner transport stream with the PLP already selected and need no external decapsulator. On a dedicated server the PCIe cards expose standard Linux DVB devices, so T2-MI handling belongs to your software stack — workable, but work you own.
Is the stream filtered before it reaches me, or can I select PIDs?
Nothing is filtered on your behalf — the selection is yours, made per session in the tuning request. Use pids=all and the complete multiplex arrives, every service with the PSI/SI tables intact. Use an explicit list such as pids=0,17,100,101 and only those elementary streams cross the link, which is how you avoid saturating a WAN path with channels you would discard on arrival. The only processing applied regardless is decapsulation where MPTS or T2-MI encapsulation is present, and unwrapping a container does not remove anything from inside it. With pids=all, analysis behaves exactly as against a local tuner card: tsp from TSDuck or Astra's analyzer shows the full service list, PAT, PMT and elementary stream PIDs.
Which tier is cheapest?
It depends on the shape of your requirement, not on the headline price. Locked is roughly 26–29% cheaper per unit than unlocked at equivalent tiers, so it wins for a small number of known transponders. Once a single position carries many frequencies you need, the position becomes cheaper than the frequencies individually. When demodulator count is the binding constraint, a multi-card chassis changes the arithmetic again.
Can I mix tiers in one deployment?
Yes, and most mature deployments do. The common pattern is locked tuners carrying the stable production lineup, one unlocked tuner kept for scanning and EPG, and dedicated hardware where density and co-location genuinely pay. The most frequent hybrid is simpler still: an operator who already owns servers, CAMs and GPUs adds the transponders they are missing as €10 add-on frequencies on their existing dedicated server or VPS, and feeds the hardware already in the rack.
What happens to a locked tuner if the broadcaster changes frequency?
The locked frequency has to be updated to match, since the tuner is provisioned for a specific transponder. This is a routine change rather than an architectural one. It is also the reason the tier suits stable lineups: if your frequencies change often, the flexibility of an unlocked tuner is worth its premium.